Skip to content

Hotfix v1.2.1: pin postcss >=8.5.10#36

Merged
revtex merged 1 commit intomainfrom
hotfix/v1.2.1-postcss
Apr 25, 2026
Merged

Hotfix v1.2.1: pin postcss >=8.5.10#36
revtex merged 1 commit intomainfrom
hotfix/v1.2.1-postcss

Conversation

@revtex
Copy link
Copy Markdown
Owner

@revtex revtex commented Apr 25, 2026

Resolves Dependabot alert #1: "PostCSS has XSS via unescaped </style> in CSS stringify output" (medium).\n\nPostCSS is a dev-only transitive dep of Vite/Tailwind and never reaches the production runtime, but pinning it removes the alert and ensures contributors build against the patched version. Adds a pnpm overrides entry; lockfile updated to 8.5.10.

Resolves the Dependabot alert: PostCSS XSS via unescaped </style> in CSS stringify output. PostCSS is a dev-only transitive of Vite/Tailwind and never reaches the production runtime, but pinning it removes the alert and ensures contributors build against the patched version. Bumps frontend version to 1.2.1.
@revtex revtex merged commit 7feb493 into main Apr 25, 2026
7 checks passed
@revtex revtex deleted the hotfix/v1.2.1-postcss branch April 25, 2026 22:53
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

1 participant